Possibly a bit too advanced for here, but has anyone any experience of HTML/JAVA forms that submit to a database (in this case PostgreSQL)? We're getting a lot of triggers on the WAF with OWASP policies applied. There's been some tuning, but still, simple free form text boxes get blocked, things like " UPDATE number to 07888554443"
It's clearly seeing it as SQLi but I mean come on, surely the WAF isn't that stupid?
It's clearly seeing it as SQLi but I mean come on, surely the WAF isn't that stupid?